Malicious Groovy Plugin Deployment in JFrog Artifactory

This rule detects the creation of a .groovy file within a plugin directory related to JFrog Artifactory, followed by the execution of suspicious child processes (e.g., shell, curl, wget) by the Artifactory process within a short timeframe. This behavior is indicative of an attacker attempting to achieve remote code execution by deploying a malicious plugin.